GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Josh Bressers (joshbressers@infosec.exchange), page 2

  1. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Saturday, 07-Dec-2024 01:50:10 JST Josh Bressers Josh Bressers
    in reply to
    • Electronic Frontier Foundation
    • Fiona Krakenbürger
    • Sovereign Tech Agency

    @krakenbuerger @eff @sovtechfund I will totally take you up on that!

    In conversation about 6 months ago from infosec.exchange permalink
  2. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 06-Dec-2024 21:52:21 JST Josh Bressers Josh Bressers
    in reply to
    • daniel:// stenberg://

    @bagder there are some choice quotes you can use in this article

    https://cyberscoop.com/cisa-secure-by-design-house-hearing/

    In conversation about 6 months ago from infosec.exchange permalink
  3. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 06-Dec-2024 11:37:27 JST Josh Bressers Josh Bressers
    • Electronic Frontier Foundation

    I'm looking for a new hoodie (suggestions welcome)

    I have a few requirements. It has to be black and it has to be zip up

    Bonus points for hacker, open source, or privacy focus

    I'm currently leaning towards this from @eff

    https://shop.eff.org/products/stay-golden-hooded-sweatshirt?variant=42581380694195

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.shopify.com
      Stay Golden Hooded Sweatshirt
      Features EFF's mission in metallic copper with glow-in-the-dark details. Stay Golden is a tribute to our resilience and power together through darkness. Heavier-weight 20/80 polycotton with minimal shrinkage, raglan sleeves, and gunmetal zipper. This roomy fit looks great on all bodies. Size Chart.
  4. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 06-Dec-2024 03:27:04 JST Josh Bressers Josh Bressers

    I just got my first "supply chain predictions for 2025" email!

    I would start a thread asking for supply chain predictions, wrong answers only

    except ... yeah

    In conversation about 6 months ago from infosec.exchange permalink
  5. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 06-Dec-2024 00:00:04 JST Josh Bressers Josh Bressers
    in reply to
    • daniel:// stenberg://
    • Ecosyste.ms

    @bagder That number probably came from the episode with Brian Fox from Sonatype. 700K was the number of malicious packages :)

    I like to look at the data from @ecosystems

    They are tracking 10 million open source projects, 2.7 million of those published something in the last year

    Of those 2.7 million

    About 20,000 have more than one million downloads

    Which is still a pretty wild number. And the Ecosyste.ms data doesn't have download numbers for everything, so there are generous error bars

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Ecosyste.ms
      Tools and open datasets to support, sustain, and secure critical digital infrastructure.
  6. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 04-Dec-2024 21:43:59 JST Josh Bressers Josh Bressers
    in reply to
    • Hobson Lane
    • SpaceLifeForm
    • kurtseifried (he/him)

    @hobs @SpaceLifeForm @kurtseifried youch

    This lines up with how I’ve seen commercial entities deal with weird bugs. It’s probably expensive to fix and cheap to ignore

    I do think it’s something open source can do better than closed. It’s probably hard to fix and barely affects anyone, but if it affects the right nerd, they’ll get it done because it’s interesting

    In conversation about 6 months ago from gnusocial.jp permalink
  7. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 04-Dec-2024 06:59:55 JST Josh Bressers Josh Bressers
    in reply to
    • kurtseifried (he/him)
    • Ben Faulhaber
    • runZero, Inc

    @fromthesocks @kurtseifried I don’t know of anything, but I’m not an expert :)

    I wonder if @runZeroInc can do something here (they have a free version you should check out)

    In conversation about 6 months ago from infosec.exchange permalink
  8. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 03-Dec-2024 04:18:41 JST Josh Bressers Josh Bressers
    • kurtseifried (he/him)

    @silhouette @kurtseifried We do have a very North American view of things

    I do hope Europe sees success with NIS2. It's all a pretty big deal and it's clear the EU gets it

    Sadly I don't see a lot of positive movement on any of this for the foreseeable future in the US

    In conversation about 6 months ago from infosec.exchange permalink
  9. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 02-Dec-2024 23:22:44 JST Josh Bressers Josh Bressers
    • Matthew Miller

    @mattdm Exactly!

    In conversation about 6 months ago from infosec.exchange permalink
  10. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 02-Dec-2024 23:18:14 JST Josh Bressers Josh Bressers

    I have a thought brewing in my brain, but I'm not sure if it makes sense

    Dealing with security flaws in dependencies often falls to #appsec teams, but should it? It's a different skill I think, closer to an #OSPO role than a security role

    In conversation about 6 months ago from infosec.exchange permalink
  11. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 02-Dec-2024 20:54:27 JST Josh Bressers Josh Bressers
    • Thomas Depierre
    • kurtseifried (he/him)

    @Di4na @kurtseifried goodness no, I would never use my own money to buy a MacBook

    It’s my work machine, I’m waiting for it to age out so I can get a Linux machine

    In conversation about 6 months ago from infosec.exchange permalink
  12. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 02-Dec-2024 12:00:01 JST Josh Bressers Josh Bressers

    All the security Apple has put into OSX 15 is starting to give me Windows Vista vibes

    I will not be at all surprised if these "security features" backfire

    In conversation about 6 months ago from infosec.exchange permalink
  13. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 02-Dec-2024 03:58:20 JST Josh Bressers Josh Bressers

    Don't let social media define who you are

    Let your pent up anger and rage define who you are

    In conversation about 6 months ago from infosec.exchange permalink
  14. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Saturday, 30-Nov-2024 05:42:52 JST Josh Bressers Josh Bressers

    It’s called cyber Monday so we remember cyber Pearl Harbor

    In conversation about 6 months ago from infosec.exchange permalink
  15. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 29-Nov-2024 09:02:41 JST Josh Bressers Josh Bressers
    in reply to
    • Simple Nomad

    @simplenomad No way

    You just tell him it’s what the force wanted Luke to do so he could help his father fulfill the prophecy

    In conversation about 6 months ago from infosec.exchange permalink
  16. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 29-Nov-2024 00:04:36 JST Josh Bressers Josh Bressers
    • Simon Phipps

    @webmink I don’t feel like this is the message I’m seeing in public

    I feel it’s more like the foundations are saving open source from regulation

    I need to ponder this

    In conversation about 6 months ago from infosec.exchange permalink
  17. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 28-Nov-2024 22:05:36 JST Josh Bressers Josh Bressers
    in reply to
    • kurtseifried (he/him)
    • Simple Nomad
    • Stuart Ward

    @xplora1a @simplenomad @kurtseifried I’m not sure I would make such a brazen statement

    But yes :)

    In conversation about 6 months ago from infosec.exchange permalink
  18. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 28-Nov-2024 22:01:01 JST Josh Bressers Josh Bressers
    • Simon Phipps
    • Thomas Depierre

    @Di4na @webmink I agree with this take. We frame this discussion as protecting the developers, but developers have options

    I’ve yet to see the conversation treating this as helping the consumers of open source (who don’t have options)

    Putting requirements on open source projects would no doubt end with a bunch of developers closing their projects

    That’s the problem everyone should be talking about, yet we frame it as helping developers avoid a risk they can already avoid by quitting

    In conversation about 6 months ago from infosec.exchange permalink
  19. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 27-Nov-2024 23:30:52 JST Josh Bressers Josh Bressers
    in reply to
    • Viss
    • da_667
    • Taggart :donor:

    @Viss @mttaggart @da_667

    Here's a better graph. This is just the WP Plugins removed with 2024 still there for scale

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/555/393/028/707/569/original/934b4e99f0e3cdb3.png
  20. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 27-Nov-2024 23:09:24 JST Josh Bressers Josh Bressers
    in reply to
    • Viss
    • da_667
    • Taggart :donor:

    @Viss @mttaggart @da_667 I graphed the CVEs with the Kernel and wordfence, patchstack, and wpscan removed (those are all the wordpress plugin bug bounty CNAs)

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/555/299/452/701/012/original/e6b0ccdca04715d8.png
  • After
  • Before

User actions

    Josh Bressers

    Josh Bressers

    VP of Security at Anchore - Podcaster (http://opensourcesecuritypodcast.com http://hackerhistory.com) - Blogger (http://opensourcesecurity.io) - He/Him

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          138318
          Member since
          20 Jun 2023
          Notices
          83
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.